What matters in AI.

Subscribe

Learn / AI security

Definition · AI security

AI security posture management

AI security posture management (AI-SPM) is a set of security tools that discover, monitor, and remediate AI-specific risks — exposed model weights, over-permissioned AI service accounts, unsecured training data, and misconfigured model APIs — across an organization's cloud AI systems. Security vendors coined the term to extend existing cloud and data security posture tools into AI infrastructure.

Last reviewed

Key points

  • Security vendors, not a standards body, coined AI-SPM. Palo Alto Networks, Wiz, Zscaler, and Orca each publish their own definition, and each also sells cloud or data security posture management.
  • The risk list is consistent across vendors: exposed model weights, over-permissioned AI service accounts, unsecured or poisoned training data, and misconfigured model APIs.
  • AI-SPM tools discover AI assets first — shadow AI, unsanctioned models, managed services like Amazon Bedrock — because most organizations lack a complete map of the AI they already run, then check each one against the risk list.
  • Vendors disagree on whether AI-SPM is new. Wiz says it "extends both disciplines" (CSPM and DSPM) "into the AI layer"; Zscaler says it covers threats those tools "miss."
  • No independent definition exists. Every account of AI-SPM, this one's raw material included, traces back to a company selling a product with that name.

AI-SPM is a security vendor’s name for checking AI systems the way cloud security posture management already checks cloud infrastructure: find every asset, then check it against a known list of ways it goes wrong.

How it works

AI-SPM tools start by finding AI assets an organization did not know it had — shadow AI, models added without approval, and managed services such as Amazon Bedrock alongside self-hosted models. Wiz makes discovery the headline of its own definition, because most organizations lack a complete map of the AI they already run.

Once found, each asset is checked against a consistent risk list: exposed model weights, AI service accounts with more permission than they need, training data left unsecured or data poisoninged, and misconfigured APIs an outsider could query directly. Zscaler frames this as covering “AI-specific threats that cloud security posture management (CSPM) and data security posture management (DSPM) tools miss” — the same problem categories, applied to assets those older tools never inventoried.

Why it matters

The risks are concrete even though the label is new. An exposed weights file is a stolen model, not a warning — the precondition for model extraction rather than paying to train one. An over-permissioned AI service account is a lateral-movement path the moment anything calls it, the failure excessive agency describes for an agent’s own permissions.

What is new is not the category of problem. It is where it now hides: model registries and managed AI services a generic cloud scan does not know to inventory. AI-SPM’s real contribution is the asset list, not a new kind of risk.

Where definitions disagree

Every vendor selling AI-SPM also sells CSPM, DSPM, or both, and each needs AI-SPM to look like a genuinely new product tier rather than a checkbox added to an existing one. Their own descriptions split. Wiz states plainly that AI-SPM “extends both disciplines into the AI layer.” Zscaler says it covers threats CSPM and DSPM “miss,” yet describes all three working “as a unified security stack.”

On the risk lists they publish, AI-SPM names the AI-specific instance of two already-established problems — cloud misconfiguration and unsafe data handling — rather than an attack surface CSPM and DSPM are structurally unable to reach. No standards body, academic definition, or neutral source was found stating otherwise; every definition available, this one included, is built from vendor material describing a vendor’s own product category.

Questions and answers

Is AI-SPM different from CSPM or DSPM?

The vendors that sell it disagree. Wiz describes AI-SPM as extending both cloud security posture management (CSPM) and data security posture management (DSPM) into the AI layer. Zscaler says it covers AI-specific threats those tools miss, while running alongside them as one stack. Either way, AI-SPM checks the same kinds of problems — misconfiguration, exposed data, excess permissions — on AI assets that CSPM and DSPM were not built to see.

Who defines what AI-SPM means?

Security vendors. Palo Alto Networks, Wiz, Zscaler, and Orca Security each publish their own definition, and each also sells cloud or data security posture management products the new term extends. No standards body or independent researcher has published a neutral definition.

Sources

  1. What Is AI Security Posture Management (AI-SPM)?Palo Alto Networks
  2. AI Security Posture Management (AI-SPM): How It WorksWiz
  3. What Is AI Security Posture Management (AI-SPM)?Zscaler
  4. What is AI-SPM (AI Security Posture Management)?Orca Security

Guides that use this term